Cross-Product Tag Behavior

Tags created in one Tenable product can influence how assets appear, are scored, and are governed in other Tenable products, but the direction of flow matters. This topic explains how tags move across the Tenable platform, what capabilities they carry at each layer, and where the boundaries are.

How Tenable One Vulnerability Management Tags Flow into Tenable One

Tags created in Tenable One Vulnerability Management (cloud) automatically synchronize into Tenable One and appear as Business Context segments in Tenable One dashboards and Tenable Exposure Management.

  1. A tag value is created in Tenable One Vulnerability Management (manually or via a dynamic rule).
  2. Assets that match the tag are grouped under that Category:Value pair.
  3. On the next sync cycle, the tag and its asset membership propagate to Tenable One.
  4. In Tenable One, each tag value becomes a Business Context segment with its own Cyber Exposure Score, Asset Exposure Score, Asset Criticality Rating distribution, and remediation maturity score.
Note: Tenable Security Center Asset Tags do not automatically flow into Tenable One, because Tenable Security Center is on-premises and operates independently. If your organization holds a Tenable Lumin or Tenable One license, you can enable Tenable One Synchronization to send IPv4 addresses within Static and Dynamic Asset Tags into Tenable One Vulnerability Management as tags, which then flow into Tenable One as Business Context using the mechanism described above. DNS Name List, LDAP Query, Combination, and Import Asset Tags are not eligible for synchronization, and Tenable Security Center's free-form Labels never sync. See Tags in Tenable Security Center for details. Without Tenable One Synchronization configured, only the Tenable One Vulnerability Management portion of a hybrid deployment contributes to Business Context in Tenable One.

Business Context in Tenable One

Within Tenable One, each tag value from Tenable One Vulnerability Management becomes a scoped view of your risk posture. For each tag, Tenable One calculates:

  • Cyber Exposure Score (0–1000) — overall exposure score for assets with that tag
  • Asset Exposure Score (0–1000) — asset-level risk weighting
  • Asset Criticality Rating (1–10) — asset criticality within the tag segment
  • Vulnerability Priority Rating (0.1–10.0) — vulnerability exploitability weighting
  • Assessment Maturity (grades A–F) — how thoroughly assets in the segment are being scanned
  • Remediation Maturity (grades A–F) — how effectively vulnerabilities in the segment are being closed

These per-tag scores let security leaders benchmark different business units, environments, or compliance scopes against each other — for example, comparing the Cyber Exposure Score of your production environment tag against your development environment tag.

Tip: Plan your tag taxonomy before creating tags, because each tag value becomes a standalone Business Context segment. Avoid creating one tag per individual team member or ephemeral asset group — focus on durable, reportable segments such as Business Unit, Environment, or Compliance Scope.

Tag-Scoped Risk Metrics

Metric Range Meaning
Cyber Exposure Score 0–1000 Overall cyber exposure for the tag segment (lower is better; 0 = no exposure)
Asset Exposure Score 0–1000 Asset exposure weighting — combines Asset Criticality Rating and Vulnerability Priority Rating
Asset Criticality Rating 1–10 Asset criticality based on device type, internet exposure, and other signals (higher = more critical)
Vulnerability Priority Rating 0.1–10.0 Vulnerability exploitability and threat context (higher = more urgent to remediate)
Assessment Maturity A–F Scan coverage and frequency for assets in the segment (A = best coverage)
Remediation Maturity A–F Speed and thoroughness of remediation activity in the segment (A = fastest remediation)

Tags in Tenable Exposure Management

Tenable Exposure Management presents three tag types: Tenable One Tags (native, fully editable), Tenable One Vulnerability Management Tags (read-only), and External Tags (from Cloud Security, Identity Exposure, or third parties — asset-level only). See Tags in Tenable Exposure Management for the full capability comparison.

The data flow from Tenable One Vulnerability Management into Tenable Exposure Management follows five steps.

  1. Tags and asset data are ingested from Tenable One Vulnerability Management into Tenable One.
  2. Tag membership is applied to assets in the Tenable One inventory.
  3. Risk scores (Cyber Exposure Score, Asset Exposure Score, Asset Criticality Rating) are calculated per tag segment.
  4. Tags appear in Tenable Exposure Management Inventory, where they can filter assets and scope Exposure View Cards.
  5. Dashboard widgets reflect tag-scoped data within up to 24 hours of membership changes.

Only Tenable One Tags support Dashboard filtering in Tenable Exposure Management. Tenable One Vulnerability Management Tags and External Tags cannot be used as Dashboard-level filters.

Using Risk Scores as Tag Rule Filters

When your Tenable One Vulnerability Management instance has an active Tenable One license, Asset Criticality Rating and Asset Exposure Score become available as tag rule filter inputs. This creates a feedback loop: risk scores drive tag membership, and tags drive access control and reporting.

For example, a tag rule built on the Asset Criticality Rating and Asset Exposure Score filters — expressed in the rule builder as ACR ≥ 8 AND AES ≥ 650 — automatically tags the highest-risk, highest-exposure assets in your environment. As scores change over time — assets become more critical, new vulnerabilities are discovered, patches are applied — tag membership updates automatically on the next rule evaluation cycle.

Note: Asset Criticality Rating values are recalculated every 24 hours. Allow up to 24 hours after an asset's first scan for its Asset Criticality Rating to appear, and then the tag rule evaluates on its next processing cycle.

Cross-Product Behavior Summary

The following table summarizes tag capabilities across products. Tenable One Tags refers to tags created natively in Tenable Exposure Management; Tenable One Vulnerability Management Tags refers to tags created in Tenable One Vulnerability Management that sync to Tenable One; Tenable Security Center Asset Tags refers to on-premises Tenable Security Center's typed asset-grouping Asset Tags; External Tags refers to third-party tags surfaced in Tenable Exposure Management; Tenable One Attack Surface Management Tags refers to tags within Tenable One Attack Surface Management.

Capability Tenable One Vulnerability Management Tags Tenable One Tags External Tags (Tenable Exposure Management) Tenable Security Center Asset Tags Tenable One Attack Surface Management Tags
Structured Category:Value Yes Yes Varies by source No (typed asset list) No (name + value type)
Dynamic rules engine Yes Yes No Yes — Dynamic and Combination Asset Tags No
Flows to Tenable One Yes Native Not applicable (already in Tenable Exposure Management) Partially — via optional Tenable One Synchronization (IPv4 Static/Dynamic Asset Tags only, requires a Tenable Lumin or Tenable One license) No
Business Context / Cyber Exposure Score per tag Yes Yes No No No
Exposure View Card scoping Yes Yes No No No
Dashboard filtering (Tenable Exposure Management) No Yes No No No
Inventory search / filter Yes (Tenable Exposure Management, Tenable One Vulnerability Management) Yes Yes (Tenable Exposure Management inventory) Yes (Tenable Security Center only) Yes (Tenable One Attack Surface Management only)
Role-based access control / access group scoping Yes (Tenable One Vulnerability Management + Tenable Exposure Management) Yes No Shared with specific users per local security policy No
API management Yes (REST API) Yes (via Tenable One Vulnerability Management API) No (source system) Yes (Tenable Security Center REST API — asset resource) Yes (Tenable One Attack Surface Management REST API)